Advertisement
Promo

Security threats Toolkit

UK government and IBM trial secure Linux

Graeme Wearden ZDNet.co.uk Tom Espiner ZDNet.co.uk

Published: 27 Apr 2006 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Cabinet Office and IBM are working together on a secure open source environment for public and private sector organisations.

The Central Sponsor for Information Assurance (CSIA) said this week that the initiative had been launched to assure public and private sectors that Linux could provide security in a complex environment.

The design is based on Security Enhanced Linux (SELinux) and IBM Websphere, a mandatory access control (MAC) application, which gives "need to know" access to security.

"We've been looking at Websphere middleware to say we can apply SELinux and a suite of applications with a security policy in a complex environment," Stephen Marsh, director of CSIA, told ZDNet UK.

On Unix and Windows the administrative privilege rights can allow the wrong people to get unrestricted access to a system, said Marsh. "Mandatory access is controlled by the security policy, which defines what the administrator can do. The administrator can only do what the security policy says you can do, even if you escalate the privilege to root user," Marsh explained.

Hackers commonly gain control of systems by giving themselves administrative access as the root user, allowing them all rights and permissions in all modes.

Open source software has been growing in popularity in recent years, primarily on the server but increasingly on the desktop, too. The CSIA is keen to test it from a security point of view.

"Linux is emerging from academic and developer communities, and we wanted to see how it could work in a complex business environment," said Marsh. "That meant work developing tools to allow systems administrators to simply apply a security policy."

Over the next month IBM, with partners Tresys and Belmin, will pilot Websphere in Durham and Darlington Health Trust. CSIA anticipates a smooth crossover from the Trust's existing Linux platform to SELinux.

"SELinux is a good example of how you take security to the next generation," said Adam Jollans, IBM Linux strategy manager. "We wanted to have wider access between government departments, but also wanted to increase the level of security, without locking down functions."

CSIA affirmed its commitment to encourage the development of secure open source architecture for public sector organisations, but said it would also work with vendors and recommend proprietary products where appropriate.

"It is government policy to use open source where we can," Harvey Mattinson, head of accreditation at the CSIA, told ZDNet UK. "We have a good working relationship with Microsoft, but we're agnostic — we work with everybody."

"We're trying to provide a menu of different techniques in transforming government architecture," said Marsh.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
70 out of 142 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters